Moka Solutions / legal support@mokasolutions.dev

Legal / Security

Security

How to report a security vulnerability in our apps or services, and what you can expect from us.

Version 1.0 · Effective 29 September 2026

Reporting a vulnerability

If you think you have found a security problem in one of our apps, websites or licence servers, please write to support@mokasolutions.dev with "Security" in the subject. Include what you found, how to reproduce it, and what impact you think it has. You can write in English or Italian.

We will:

  • confirm we received your report within 3 working days;
  • keep you informed while we investigate and fix it;
  • credit you when we publish the fix, if you wish.

Please give us reasonable time to release a fix before disclosing the issue publicly — normally 90 days, or less if we agree on it together.

Good-faith research

We will not take legal action against research carried out in good faith that respects these rules:

  • test only against your own devices, accounts and licences;
  • don't access, change or delete other people's data, and stop as soon as you reach any;
  • don't degrade our services (no denial-of-service or high-volume automated testing), and don't use social engineering or physical attacks;
  • don't publish or share licence keys, and don't use a vulnerability beyond what is needed to show it.

We don't run a paid bug bounty, but we are two people who genuinely appreciate the help.

A machine-readable version of this policy is at /.well-known/security.txt.